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MEMORANDUM FOR: Deputy Director of Central Intelligence 


FROM: John F. Blake 
Deputy Director for Administration 


SUBJECT: a Security Review - Interim Report 


Memorandum for DDA from DDCI, dated 
13 August.1978, Subject: <A Request 
for a Security Review and Assessment 


i. Action Requested: None; for information only. 


2. Background: Following the mid-August 1978 revelation 
that a former Agency employee had sold classified information 
to the Soviets, you directed a comprehensive review of tie 
Agency's security policies and procedures and called for an 
interim report by 1 September 1978. Subsequently, the Directer 
has expanded the scope of the interin report to include: 

(a) a cataloguing of specific improvements in the Agency's 
security program realized since his appointment and by his 
initiatives; and (b) a listing of procedures currently being 
initiated to further improve the security of classified infor- 
mation. Pursuant to those directions, this interim report is 
submitted. 


3. Staff Position: In April 1977, following the reve- 
lations of the Moore and Boyce/Lee espionage cases, a conpre- 
hensive impact study was completed by the Office of Security. 
As a consequence, the Director caused several security tniti 
and gave the necessary impetus to others which have been su 
fully implemented to the enhancement of Agency and Intellig 
Community security. Agency programs successfully implen 
include: 
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A rigorous staff personnel security 
stigation program 
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bd. Expanded security education and reindoc- 
trination efforts throughout the Agency. 


c. Enhancement of appraisal criteria in 
Industrial Security Approvals. 


d. Initiation of the Industrial Contractor 
Polygraph Program. 


e. Increased spot checks of briefcases, 
packages and parcels at all Agency facilities in. 
the Washington Metropolitan area. - 


£. Initiation of a program of unannounced ra 
security audits of Agency contractor facilities. 


STATINTL 


h. A personal interest in and involvement by 
the Director and senior Agency managers in the 
‘adjudication and penalty assessment procedures 
involving Agency employees whe have violated secu- 
rity regulations. 


Programs initiated by the Director to tighten the secu- 
rity of the Intelligence Community have inciuded: 


a. The strengthening of the Director of Central 
Intelligence Security Committee as a focal point for 
reporting and tracking unauthorized disclosures and 
for raising security consciousness in the Community. 


b. Maintaining a freeze since 1 June 1977 on the 
total number of sensitive compartmented clearances 
throughout the Community. 


c. Initiation of a program to revalidate security 
clearances by effecting zero-based reviews in Intelli- 
gence Community and contractor facilities. 


d. Directing contracting and legal authorities to 
Strengthen the security provisions of contracts between 
commercial firms and Intelligence organizations. 
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I can assure you the Director of Security has and 
is continuing to dedicate all available personnel resources, 
aS well as his personal attention, to the programs outlined 
above. 


5 
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In accordance with your specific request of 13 
1 


3 
1978, a comprehensive review of the Agency's security po 
and procedures has commenced. 


During the week of 21 August the organization and 
Staffing of a Security Review Task Force was undertaken. 
The Task Force will approach the review in three segments. 
Each segment staff will function under the leadership of a 
senior experienced officer. The segments will address, 
Separately, Personnel Securit » Physical Security, and Iafor- 
mation Control and Protection. The magnitude of the task 
is awesome, and the Director of Security estimates a compre- 
hensive review will require a minimum of sixty (60) days. 


The Personnel Security Segment of the Task Force 
intends to investigate all periods of an employee's career 
from preemployment processing through post-employment counseling. 
It is their intent to survey personnel recruitment and assign- 
ment policies and procedures which are quite varied from 
directorate to directorate and from office to office. Although 
the emphasis in this segment will be on staff employees, the 
Task Force will also Survey the several other types of individuals 
Who are utilized by the Agency. The entire security clearance 
process from pre-field investigation to final adjudication will 
be reviewed, as will the vast number of policies and procedures 
that pertain during the employment phase. 


The employment phase topics include Security indoctri- 
nation/reindoctrination; marriage, including marriage to an 
alien; outside activities; handling of misconduct incidents; 
counterintelligence review of high risk personnel and organiza- 
tional units; the reinvestigation program; security and 
Suitability reviews for overseas candidates; Agency management 
responsibilities; and the Personnel Evaluation Board. Finally, 
the Agency's out-processing policies and procedures as well as 
current policies relative to post-employment counseling will be 
addressed under this segment, , 


The Task Force will exclude from its review the 
Operational security policy procedures and practices concerning 
those individuals who are utilized by the Directorate of 
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Cperations in an operational and informational capacity such 
as double agents and clandestine sources. That policy is a 
DDO responsibility. 


he Physical Security Segment has an enormous "ask 
at hand. This segment will limit the scope of their review 
by concentrating primarily upon the physical security progran 
as it is pursued within the Headquarters Bullding. The sud- 
Stantive areas which constitute the physical security program 
of the Agency can be examined in relation to operations within 
the Headquarters Building within a reasonable time frame. 


Essentially our physical security policies and proce- 
dures at Headquarters have been adopted in our domestic and STATIN 
overseas facilities, and available resource and time constraints 


dictate that but cursory reference be given to th ire: 
scope of the overseas 
during the survey. Siz > Ul SView WL not specifically 


cover the physical security aspects of our industrial security _ 
program because that subject has been thoroughly reviewed during 
the past year. And finally, we consider the technical threat 

as well as the measures which have been implemented to counter 
this threat as beyond the scope of this review. 


: The Physical Security Segment of the Task Forces will 
address thoroughly the policies and procedures pertaining to: 
perimeter security; building security; access controls for 
all types of people from staff employees to vendors; baiges; 
entry and exit inspection procedures: internal personnel control; 
storage of classified information; the Agency's guard program; 
intrusion detection systems and other monitoring equipment; 

after hours security procedures and the security violation pro- 
aram. ’ 


The Information Controi and Protection Seguient pro- 
poses to review the application by CIA of directives and 
regulations governing the production, marking, Classification, 
reproduction, transmission, inventory and overall control of 
Classified information. These will be reviewed for current 
applicability to determine whether rules are being observed, 
and, if so, whether a significant measure of control results 
from their observance. The scope of this segment will include 
an inquiry into the level and efficiency of employee training 
in document control procedures; an examination of the posibility 
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of handling information at lower levels of classification 

or conparimentation; exploration of methods to reduce the 
amount of classified material retained in the Agency; inquiry 
into the efficacy of current ADP and microform information 
control, and the state of pre-planning for future information 
technology requirements. Finally, we. intend to examine alter- 
native ways of controlling accountability for classified 
materials, including automated techniques. 


Obviously, to conduct the survey effectively, the 
Task Force will require the complete cooperation of the 
Agency's population. For example, to meaningfully describe 
Current procedures under the Personnel Security Sepment is 
going to require close cooperation with several offices, 
especially the Office of Personnel and the Office of Medical 
Services. Furthermore, several offices throughout the Agency 
are involved in the recruitment of personnel, and their 
cooperation will also be necessary. Consequently, it is recon- 
mended that you solicit the cooperation of all directorates 
with the members of the Task Force. : 


The Task Force will approach its task by extensive 
documentary reviews, personal interviews both within and 
external to the Agency, and by discussion within the Task 
Force which will lead to a series of recommendations concerning 
the Agency's Security program. The Task Force members have 
been exhorted to approach the task, particularly the reconmen- 
dations, with absolute objectivity and personal integrity, as 
We view the review as an opportunity to assure our security 
policies and procedures are right for the time. 


We envision a final report to be submitted to you 
by 3 November 1978. We expect that report to be in four 
parts: (a) a description of current policies and procedures; 
(b) analysis of current policies and procedures; (c) conclusions; 
and (d) recommendations. 


The current review will be thorough. We anticipate 
Specific recommendations pertaining to the restatement of the 
basic principle that Security is a command responsibility 
Within the Agency, i.e., the responsibility of each manager 
and supervisor. Furthermore, we expect to relate the apparent 
deterioration in Security discipline in the operating components 
to the reduction of professional security positions in those 
components over the past decade; in ten years the number of 
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Nevertheless, the urgency of the present situation 
calls for the implementation of improved procedures and new 
initiatives prior to completion of the formal review. Towards 
that end the following actions have been taken: 


(a) Commencing 11 September 1978 the briefcase, 
package inspection program will be expanded and con- 
ducted by the Federal Protective Officers on a routine 
basis seven days a week and twenty-four hours a day. 


(b) Commencing immediately, systematic counter- 
intelligence procedures will be established by the 
Office of Security to investigate employee accesses 
to secure areas outside of normal duty hours and to 
review the pattern of employee after-hours accesses 
to Headquarters area buildings. 


STATINTL 


(d) The Deputy Directors of the Agency are being 
directed, immediately, to establish positive, account- 
able document controls for particularly sensitive 
materiais under their cognizance. 


(e) Arrangements are being finalized for the 
Office of Security to conduct 4 Series of briefings 
of senior staffs throughout the Agency. The briefings 
will comprehensively review Security problems discovered 
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(£) The Office of Security is reminding Agency 
managers that personnel are available as speakers, 
panelists, consultants, etc, to assist command chan- 
nels in the security education and reindoctrination 
of small employee groups. As you know, the Office 
of Security recently completed a formal reindoctri- 
nation of the Agency population in a number of 
presentations to large audiences. 


4. Conclusion: In accordance with the reference, I 
assure you that the Security Review is receiving the highest 
priority and my personal attention. The scope of the task, | 


in my opinion, fully justifies a 3 November 1978 final reporting 
date. 


John F. Blake 


Distribution: 
Orig - Addressee J—-oL € (4s/2 5) 
2 - DDA ; 
- ER - @ - C/PhySD 
lor D/Security 1 - DD/PSI 


1 - OS Registry 
3 - Task Force ; 
STATINTES POU/SSDA_ lems (31 Aug *78) 


STATINTPRIGINATOR: 


3 1 AUG 1978 
Date 


obert W. Gambino 
Director of Security 
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